Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2024-04914
HistoryJan 16, 2024 - 12:00 a.m.

TOTOLINK EX1200T Command Injection Vulnerability

2024-01-1600:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
totolink
ex1200t
command injection
vulnerability
china
gion electronics
arbitrary command execution
wi-fi
range extender
version v4.1.2cu.5232_b20210713
command special characters

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

49.4%

TOTOLINK EX1200T is a Wi-Fi range extender from China’s Gion Electronics (TOTOLINK). A command injection vulnerability exists in TOTOLINK EX1200T version V4.1.2cu.5232_B20210713, which stems from the main method failing to properly filter construct command special characters, commands, and so on. An attacker can exploit this vulnerability to cause arbitrary command execution.

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

49.4%

Related for CNVD-2024-04914